CVE-2026-54350 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-54350 requires immediate attention.
· 7 min read
Executive Summary
CRITICAL: CVE-2026-54350 affects npm @budibase/server and can let an unauthenticated attacker read or modify data in published Budibase apps that use PUBLIC non-SQL queries. The flaw is in JSON parameter handling: attacker-controlled input is inserted into a raw JSON body and parsed back into an object, allowing query filters to be rewritten. In practical terms, a single crafted HTTP request may turn a narrow query into a collection-wide read or write.
This is especially urgent for solo developers and small teams running public forms, portals, or internal tools exposed to the internet. If you have any published Budibase app with a PUBLIC MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body query, assume the app is at risk until patched or isolated.
Immediate Action
- Patch or upgrade immediately to the first fixed release of Budibase /
@budibase/serveronce available. If you do not know the fixed version yet, use the vendor advisory and release notes: vendor advisory. - Disable or remove PUBLIC queries on any published app that uses non-SQL datasources. If the app must stay online, temporarily require authentication or take the app offline.
- Rollback exposed public forms to a previous safe build if you cannot patch today.
- Isolate the service behind VPN, IP allowlisting, or a reverse proxy auth layer until remediation is complete.
- Rotate secrets and review data exposure if the app handled sensitive records; assume read access may have occurred.
- Check logs now for unusual POSTs to
/api/v2/queries/with suspicious JSON parameter values.
Affected Versions
@budibase/server <= 3.39.0vulnerableBudibase/budibaseserver builds up to HEADfeab995(released 2026-05-20) vulnerable@budibase/serversafe version:TODO_FIXED_VERSIONand laterBudibase/budibasesafe release:TODO_FIXED_RELEASEand later
Not affected: SQL datasources routed through parameterized interpolation paths are not impacted by this issue.
Resolution Guide
JavaScript / npm
npm install @budibase/server@TODO_FIXED_VERSION
# or
npm update @budibase/server
Yarn
yarn add @budibase/server@TODO_FIXED_VERSION
pnpm
pnpm add @budibase/server@TODO_FIXED_VERSION
Docker
docker pull budibase/budibase:TODO_FIXED_RELEASE
# then redeploy with the fixed tag
Linux package managers are unlikely to apply directly unless you vendor Budibase into a system package. If you do, rebuild from the fixed source release and redeploy.
Hardening until patched
# Remove PUBLIC access from risky queries
# In Budibase UI: Query settings -> Role -> require authenticated role instead of PUBLIC
# If possible, disable public app access at the reverse proxy
# Example: require basic auth or VPN for /api/v2/queries/*
Minimal code fix idea — escape JSON metacharacters before parsing, or better, stop templating raw JSON and use structured parameter binding:
// Pseudocode: do not inject raw text into JSON
const safeValue = JSON.stringify(parameters.name);
const json = JSON.parse(`{ "name": ${safeValue} }`);
Better fix: validate and bind parameters as data, not as string substitution. For Mongo-style filters, enforce an allow-list of expected keys and reject any injected operators such as $exists, $ne, or nested objects where a scalar is expected.
Detection & Verification
Check your installed version
npm ls @budibase/server
# or, in a Budibase container:
docker image inspect budibase/budibase --format '{{.RepoTags}}'
Search for risky PUBLIC queries
grep -R "PUBLIC" -n packages/server/src 2>/dev/null
grep -R "bodyType=json\|updateMany\|collection.find\|validateQueryInputs" -n packages/server/src 2>/dev/null
Audit published apps: look for any query using MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST with JSON body that is set to PUBLIC.
Verify the fix by sending a benign parameter and confirming it no longer alters the JSON structure. A safe request should return only the intended record, not the full collection.
curl -s -X POST "https://YOUR_HOST/api/v2/queries/YOUR_QUERY_ID" \
-H "x-budibase-app-id: YOUR_APP_ID" \
-H "Content-Type: application/json" \
--data '{"parameters":{"name":"alice"}}'
Negative test: after patching, an injection-style value such as x\",\"name\":{\"$exists\":true} should be rejected or treated as plain text, not as a filter override.
Risk and Impact
This bug can expose every document behind a PUBLIC query, including secrets, API tokens, password hashes, and internal records. In write scenarios, it can also update or delete every row/document matched by the widened filter, causing data corruption at collection scope. Because the endpoint accepts requests without a session and CSRF is not enforced on the PUBLIC path, exploitation is low-effort and can be done from any browser or script.
If you run a small team or solo project, treat this as a high-priority incident: patch first, then review logs, rotate credentials, and assume any public Budibase app using non-SQL JSON-body queries may have been exposed.